Actions
Bug #7530
openKerberos: sname/cname code and suricata documentation both wrong
Affected Versions:
Effort:
Difficulty:
Label:
Beginner
Description
In the suricata documentation the cname and sname are described as client and server name. https://docs.suricata.io/en/latest/rules/kerberos-keywords.html
But the suricata code in github, describe the krb5_cname and krb5_sname as their respective principal name:
These were contradicting, so we did a test and it looks like the the krb5_cname is the client service principal and the sname is the destination server, so it appears that both the docs and the code documentation is wrong.
Files
Updated by Victor Julien about 2 months ago
@Pierre Chifflier can you have a look?
Actions